wilpower
Junior Member
 

Posts: 67
|
 |
Re: RootKits and "Spiceworks"
« Reply #2 on: Jul 4th, 2008, 4:27pm » |
Quote Modify
|
Thanks apile Siliconman01. First the Combofix log" ComboFix 08-07-04.1 - Will Schmidt 2008-07-04 14:16:38.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.647 [GMT -7:00] Running from: C:\Documents and Settings\Will Schmidt\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\msvrc20.dll . ((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 ))))))))))))))))))))))))))))))) . 2008-07-04 14:02 . 2008-02-22 02:3369,632--a------C:\WINDOWS\system32\javacpl.cpl 2008-07-04 13:29 . 2008-07-04 13:40<DIR>d--------C:\Documents and Settings\Will Schmidt\.SunDownloadManager 2008-07-02 16:35 . 2008-07-04 09:54<DIR>d--------C:\RootKit Detection 2008-07-02 12:58 . 2008-07-04 14:14<DIR>d--------C:\Documents and Settings\Will Schmidt\Application Data\Vista Start Menu 2008-06-10 16:40 . 2008-06-13 06:10272,128-----c---C:\WINDOWS\system32\dllcache\bthport.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-04 21:04---------d-----wC:\Program Files\Java 2008-07-04 20:01---------d-----wC:\Program Files\VisualRoute 2008 2008-07-04 19:53---------d-----wC:\Documents and Settings\Will Schmidt\Application Data\MSGTAG 2008-07-04 17:13---------d-----wC:\Program Files\LetMeSee This 2008-07-04 17:08---------d-----wC:\Documents and Settings\Will Schmidt\Application Data\MailWasherPro 2008-07-03 20:47---------d-----wC:\Documents and Settings\All Users\Application Data\Google Updater 2008-07-03 16:42---------d-----wC:\Program Files\CryptoMite 2008-07-02 20:36---------d-----wC:\Program Files\POP Peeper 2008-07-02 19:53---------d-----wC:\Program Files\Vista Start Menu 2008-07-01 20:46---------d-----wC:\Program Files\SUPERAntiSpyware 2008-07-01 16:27---------d---a-wC:\Documents and Settings\All Users\Application Data\TEMP 2008-07-01 16:27---------d-----wC:\Program Files\SpywareGuard 2008-07-01 16:26---------d-----wC:\Program Files\SpywareBlaster 2008-06-13 13:10272,128------wC:\WINDOWS\system32\drivers\bthport.sys 2008-06-05 23:46---------d-----wC:\Program Files\TrojanHunter 5.0 2008-05-24 14:30---------d-----wC:\Program Files\SiteAdvisor 2008-05-17 19:30---------d-----wC:\Program Files\NEO Pro 2008-05-17 19:30---------d-----wC:\Program Files\Common Files\Wise Installation Wizard 2008-05-15 00:11---------d-----wC:\Program Files\LimeWire 2008-05-11 16:141,354,160----a-wC:\cmxp170.zip 2008-05-09 00:44---------d-----wC:\Documents and Settings\All Users\Application Data\Comodo 2008-05-09 00:41---------d-----wC:\Program Files\Comodo 2008-05-08 12:28202,752----a-wC:\WINDOWS\system32\drivers\rmcast.sys 2008-05-07 05:181,287,680----a-wC:\WINDOWS\system32\quartz.dll 2008-04-24 05:163,591,680----a-wC:\WINDOWS\system32\SET66.tmp 2008-04-23 04:16826,368----a-wC:\WINDOWS\system32\wininet.dll 2008-04-23 04:16826,368----a-wC:\WINDOWS\system32\SET5D.tmp 2008-04-23 04:1663,488----a-wC:\WINDOWS\system32\SET75.tmp 2008-04-23 04:166,066,176----a-wC:\WINDOWS\system32\SET6E.tmp 2008-04-23 04:1652,224----a-wC:\WINDOWS\system32\SET67.tmp 2008-04-23 04:16459,264----a-wC:\WINDOWS\system32\SET68.tmp 2008-04-23 04:16383,488----a-wC:\WINDOWS\system32\SET70.tmp 2008-04-23 04:16267,776----a-wC:\WINDOWS\system32\SET6C.tmp 2008-04-23 04:16233,472----a-wC:\WINDOWS\system32\SET5E.tmp 2008-04-23 04:16124,928----a-wC:\WINDOWS\system32\SET78.tmp 2008-04-23 04:16105,984----a-wC:\WINDOWS\system32\SET60.tmp 2008-04-23 04:161,159,680----a-wC:\WINDOWS\system32\SET5F.tmp 2007-04-03 14:1930,601----a-wC:\Documents and Settings\Will Schmidt\x.exe 2007-03-11 19:3714----a-wC:\Documents and Settings\Will Schmidt\getfile.dat 2004-08-12 13:3194,784--sh--wC:\WINDOWS\twain.dll 2004-08-12 13:3150,688--sh--wC:\WINDOWS\twain_32.dll 2004-08-12 13:211,028,096--sh--wC:\WINDOWS\system32\mfc42.dll 2004-08-12 13:2354,784--sh--wC:\WINDOWS\system32\msvcirt.dll 2004-08-12 13:23413,696--sh--wC:\WINDOWS\system32\msvcp60.dll 2004-08-12 13:23343,040--sh--wC:\WINDOWS\system32\msvcrt.dll 2007-12-04 18:38550,912--sh--wC:\WINDOWS\system32\oleaut32.dll 2004-08-12 13:2583,456--sh--wC:\WINDOWS\system32\olepro32.dll 2004-08-12 13:2711,776--sh--wC:\WINDOWS\system32\regsvr32.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSGTAG"="C:\Program Files\MSGTAG Status\MSGTAGStatus.exe" [2007-07-10 21:38 1820160] "DS Clock"="C:\Program Files\DS Clock\dsclock.exe" [2005-01-04 01:19 331776] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 06:18 15360] "Calendarscope"="C:\Program Files\Calendarscope\cs.exe" [2007-03-26 19:05 2027586] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-23 16:01 68856] "!1_ProcessGuard_Startup"="C:\Program Files\ProcessGuard\procguard.exe" [2005-01-20 15:24 280064] "AutoSizer"="C:\Program Files\AutoSizer\AutoSizer.exe" [2006-12-15 07:57 126976] "VistaStartMenu"="C:\Program Files\Vista Start Menu\VistaStartMenu.exe" [2008-06-27 06:25 2134528] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartupDelayer"="C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe" [2006-08-03 03:20 21504] "SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-12-19 19:37 36952] "LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 09:39 98304] "LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 18:32 155648] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35 94208] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36 114688] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32 77824] "GhostSecuritySuite"="C:\Program Files\GhostSecuritySuite\gss.exe" [2008-04-10 16:36 1302528] "DadApp"="C:\Program Files\Dell\AccessDirect\dadapp.exe" [2004-03-04 11:36 211828] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 16:19 79224] "COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-11-18 14:01 1115728] "!1_pgaccount"="C:\Program Files\ProcessGuard\pgaccount.exe" [2005-01-20 15:14 184320] "WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-04-25 10:31 333120] "DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2006-11-27 16:18 1582616] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-06-05 16:46 1046688] "VEngine"="C:\Program Files\Comodo\VEngine\VEngine.exe" [2008-05-08 17:44 335616] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-12 06:18 15360] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 18:23 443968] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "KeyScrambler"="C:\Program Files\KeyScrambler\getting_started.html" [X] C:\Documents and Settings\Will Schmidt\Start Menu\Programs\Startup\ SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-14 13:14:44 125624] Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08 262944] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveSearch"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-11-21 14:50 233472] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-27 09:01 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows] "load"= [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"= [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.SP53"= SP5X_32.DLL "VIDC.SP54"= SP5X_32.DLL "VIDC.SP55"= SP5X_32.DLL "VIDC.SP56"= SP5X_32.DLL "VIDC.SP57"= SP5X_32.DLL "VIDC.SP58"= SP5X_32.DLL "VIDC.SP59"= SP5X_32.DLL HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Digital Turtlets [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Digital Turtlets\SpamBrave for Outlook Express] [X] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Digital Turtlets\SpamBrave Lite for Outlook Express] --a------ 2007-03-12 11:39 110592 C:\Program Files\Digital Turtlets\SpamBrave Lite for Outlook Express\oewatcher.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\msncall.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\WINDOWS\\system32\\java.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 bxShield;BAxBEx File Protector;C:\WINDOWS\system32\Drivers\bxShield.sys [] R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 16:20] R1 lusbaudio;Logitech USB Microphone;C:\WINDOWS\system32\drivers\lvsound2.sys [2001-09-24 09:38] R1 TSKNF700.SYS;TSKNF700.SYS;C:\WINDOWS\system32\Drivers\TSKNF700.SYS [2006-10-24 16:29] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 16:16] R2 DCSPGSRV;DiamondCS Process Guard Service v3.000;"C:\Program Files\ProcessGuard\dcsuserprot.exe" [2005-01-20 15:25] R2 FSService;FSService;C:\Program Files\Folder Shield\FSService.exe [2006-04-13 14:05] R2 procguard;procguard;C:\WINDOWS\system32\drivers\procguard.sys [2005-01-20 15:13] R3 KeyScrambler;KeyScrambler;C:\WINDOWS\system32\drivers\keyscrambler.sys [2008-03-22 14:37] R3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2001-09-24 09:39] R3 LVVI500A;LVVI500A Service;C:\WINDOWS\system32\DRIVERS\lvvi500a.sys [2001-09-20 03:39] S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver;C:\DOCUME~1\WILLSC~1\LOCALS~1\Temp\F-Secure\BlackLight\fsbldrv.sy s [] . Contents of the 'Scheduled Tasks' folder "2008-07-03 23:30:05 C:\WINDOWS\Tasks\Advanced WindowsCare V2 Pro.job" - C:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoCare.exe "2008-06-05 03:00:16 C:\WINDOWS\Tasks\AwcProUpdate.job" - C:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoUpdate.ex - C:\Program Files\IObit\Advanced WindowsCare V2 Pro\ . ************************************************************************ ** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-04 14:19:11 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\Program Files\Spiceworks C:\WINDOWS\system32\drivers\bxShield.sys 45056 bytes executable C:\WINDOWS\system32\fsbx.ini 805 bytes scan completed successfully hidden files: 3 ************************************************************************ ** . Completion time: 2008-07-04 14:20:38 ComboFix-quarantined-files.txt 2008-07-04 21:20:33 Pre-Run: 45,187,141,632 bytes free Post-Run: 45,183,631,360 bytes free 189--- E O F ---2008-06-21 03:55:15
|